#1 (permalink)  
Old 06-15-2003, 02:08 PM
DWHS.net's Avatar
Registered User
 
Join Date: Jul 2002
Location: LA
Posts: 1,201
DWHS.net is on a distinguished road
Anyone know how to debug this intrusion.

Hello,

On a test server we managed to get it attacked and hacked with felonious information.

We know are going to try to debug it without re-installing redhat.

Any ideas on how to dig out the trojan horse or whatever the hacker did in this folder?

The logs where re-directed to dev/null so there is no record of what was done.

Maybe a good tool that can find a trojan and debug it?

Here is the hack from user rpm:

IMPORTANT: Do not ignore this email.
This message is to inform you that the rpm
package fileutils did not match the expected checksum. This could mean that
your system was compromised (OwN3D). The offending files have been removed
and replaced with the OS default. To be safe you should verify that your
system has not be compromised.

Modified Files:
..5..... /usr/bin/vdir

We are new to trojan debugging and will post any useful information if it arises. This is experimental so any suggestions are welcome.

Thanks,

cPanel.net Support Ticket Number:
__________________
DWHS Inc. - dwhs.net
Web Hosting | Business Favs | Web Hosting Times
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 11:46 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© cPanel Inc